PT-2016-4028 · Symantec · Data Center Security: Server Advanced Server+2
Publicado
2016-06-08
·
Atualizado
2021-09-09
·
CVE-2015-8798
CVSS v2.0
7.7
Alta
| Vetor | AV:A/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Symantec Embedded Security: Critical System Protection (SES:CSP) versions 1.0.x through 1.0 before MP5
Embedded Security: Critical System Protection for Controllers and Devices (SES:CSP) version 6.5.0 before MP1
Critical System Protection (SCSP) versions prior to 5.2.9 MP6
Data Center Security: Server Advanced Server (DCS:SA) versions 6.x through 6.5 before MP1 and version 6.6 before MP1
Data Center Security: Server Advanced Server and Agents (DCS:SA) versions prior to 6.6 MP1
Description
A directory traversal issue in the Management Server allows remote authenticated users to execute arbitrary code via unspecified vectors.
Recommendations
For Symantec Embedded Security: Critical System Protection (SES:CSP) versions 1.0.x, update to 1.0 MP5 or later.
For Embedded Security: Critical System Protection for Controllers and Devices (SES:CSP) version 6.5.0, update to MP1 or later.
For Critical System Protection (SCSP), update to 5.2.9 MP6 or later.
For Data Center Security: Server Advanced Server (DCS:SA) versions 6.x, update to 6.5 MP1 or later, and for version 6.6, update to MP1 or later.
For Data Center Security: Server Advanced Server and Agents (DCS:SA), update to 6.6 MP1 or later.
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Critical System Protection
Data Center Security: Server Advanced Server
Symantec Embedded Security: Critical System Protection